CVE-2026-64633Patch

MEDIUM

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

5.5/ 10 priority

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 15 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 11 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 6 mentions (2026-08-05); latest day: 1
  • 15 total mentions across 5 days

Deep dive

Activity timeline15 mentions / 5d
02356Mentions · 2026-08-04: 3Mentions · 2026-08-05: 6Mentions · 2026-08-06: 4Mentions · 2026-08-08: 1Mentions · 2026-08-10: 1PoC Mentioned / Linked · 2026-08-05: 2Active Exploitation · 2026-08-05: 1Patch / Workaround · 2026-08-04: 3Patch / Workaround · 2026-08-05: 3Patch / Workaround · 2026-08-06: 4Patch / Workaround · 2026-08-08: 1Patch / Workaround · 2026-08-10: 1Technical Details · 2026-08-04: 3Technical Details · 2026-08-05: 2Technical Details · 2026-08-06: 4Technical Details · 2026-08-08: 1Technical Details · 2026-08-10: 108-0408-0508-0608-0808-10
Signal classification5 categories
Patch
960.0%
Disclosure
320.0%
Active Exploitation
16.7%
General
16.7%
PoC
16.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-08-043
Disclosure1Patch2
2026-08-056
Active Exploitation1General1Patch3PoC1
2026-08-064
Disclosure2Patch2
2026-08-081
Patch1
2026-08-101
Patch1
Full discourse15 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-64633 (CVSS 10.0) + CVE-2026-58075 (CVSS 8.7): Unauthenticated RCE and arbitrary file read on Veeam ONE agent host 🔗FOFA Link: https://en.fofa.info/result?qbase64=dGl0bGU9IlZlZWFtIE9ORSI%3D 🎯1.1K+ Results are found on http://en.fofa.info in the past year. FOFA Query: title="Veeam ONE" 🔖Refer: https://veeam.com/kb4892 #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    Two new high‑severity CVEs (CVE‑2026‑64633 and CVE‑2026‑58075) affecting Veeam ONE, enabling unauthenticated remote code execution and file read, have been announced; a Veeam KB article is cited for remediation.

    0240834416.1K
    14.8K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Disclosure

    🚨 Upozorňujeme na RCE zranitelnost ve Veeam ONE, CVE-2026-64633. Tato zranitelnost s hodnocením CVSS 10.0 umožňuje vzdálené spuštění kódu bez autentizace na hostiteli agenta. Útočník může bez předchozího přihlášení zneužít chybu k převzetí kontroly nad zasaženým systémem, spuštění libovolného kódu a následnému narušení důvěrnosti, integrity i dostupnosti postiženého prostředí. Zranitelnost se týká verzí Veeam ONE 13.0.2.6723 a starších buildů řady 13. 📌Doporučujeme aktualizovat na verzi 13.1.0.7034 nebo novější.

    Post summary

    This post discloses a critical RCE vulnerability (CVE‑2026‑64633) in Veeam ONE with a CVSS score of 10.0, affecting versions up to 13.0.2.6723, and urges users to upgrade to 13.1.0.7034 or newer.

    02031605
    4.3K followersView on X
  • yousukezan@yousukezan
    Patch

    Veeam ONEに重大な脆弱性CVE-2026-64633が見つかり、認証不要でリモートから任意コードを実行できることが明らかになった。Veeamはこの脆弱性を含む6件の問題を修正したVeeam ONE 13.1.0.7034を公開しており、バックアップ監視基盤が標的となるリスクから速やかな更新を推奨している。 CVE-2026-64633は、監視対象ホスト上で動作するVeeam ONEエージェントに存在し、ネットワーク経由で認証なしに任意コードを実行できる。ユーザー操作やログインは不要で、到達可能なエージェントが侵害されると攻撃の足掛かりとなる可能性がある。現時点で悪用事例やPoCは公開されていない。 今回の更新では、このほかにも5件の脆弱性が修正された。CVE-2026-58075(CVSS 8.7)は認証不要で任意ファイルを読み取れる問題、CVE-2026-58074およびCVE-2026-64631(ともにCVSS 8.6)は権限を持つ、または低権限ユーザーによるコード実行やSQLインジェクション、CVE-2026-64634(CVSS 8.4)はローカル権限昇格、CVE-2026-64630(CVSS 5.3)は共有レポートデータの情報漏えいに関する問題である。 影響を受けるのはVeeam ONE 13.0.2.6723およびそれ以前のバージョン13系で、回避策は提供されていない。Veeamは13.1.0.7034への更新と、更新完了までの間はVeeam ONEエージェントへのネットワークアクセスを制限するよう案内している。 https://securityonline.info/veeam-one-cve-2026-64633-rce/

    Post summary

    The post announces a critical RCE CVE in Veeam ONE, provides a patch and mitigation steps, but no PoC or evidence of active exploitation.

    000411.4K
    15.0K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🗄️ Veeam CVE-2026-64633: unauthenticated remote code execution on the agent host. CVSS 10 critical. No auth, no interaction, full system compromise. Patch now. #cybersecurity #ciso #cto #vulnerabilities #msp #mssp https://secalerts.co/vulnerability/CVE-2026-64633?utm_campaign=x https://t.co/nu5xHjHh29

    Post summary

    The tweet highlights a critical unauthenticated RCE (CVE‑2026‑64633) in Veeam, noting an immediate patch is available.

    00012441
    876 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical flaw in #Veeam ONE. #CVE-2026-64633 CVSS: 10.0. Unauthenticated attackers can achieve #RCE on the agent host! #Patch #Patch #Patch More info: https://www.veeam.com/kb4892

    Post summary

    The post announces a critical RCE flaw in Veeam ONE, highlights the CVSS score and impact, and emphasizes the urgency of applying the vendor patch.

    01020524
    7.2K followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-64633 CVE-2017-20241 CVE-2017-20242 CVE-2025-29296 CVE-2026-0163 ..🧵👇

    Post summary

    The tweet simply lists CVE identifiers without additional context or actionable information.

    1001076
    29 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    A critical Veeam ONE vulnerability, CVE-2026-64633, allows remote unauthenticated code execution at CVSS 10.0. Update to build 13.1.0.7034 now. #Veeam #VeeamONE #CVE202664633 #RCE #RemoteCodeExecution #Vulnerability #CVSS10 #PatchNow #CyberSecurity https://securityonline.info/veeam-one-cve-2026-64633-rce/ https://t.co/VA3aiqi6rt

    Post summary

    The tweet announces a critical Veeam ONE CVE that permits remote unauthenticated code execution and provides the specific patch build needed to address it.

    00011445
    12.6K followersView on X
  • lee1981@lee1981b
    Patch

    🔥 CyberForge CVE of the Day #017 🚨 CVE-2026-64633 — Veeam ONE Unauthenticated Remote Code Execution A critical code-injection vulnerability allows a remote, unauthenticated attacker to execute code on a Veeam ONE agent host. ⭐ CVSS v4.0: 10.0 Critical ⭐ CWE: CWE-94 — Code Injection ⭐ Attack Vector: Network ⭐ Attack Complexity: Low ⭐ Privileges Required: None ⭐ User Interaction: None ⭐ Technical Impact: Total ⭐ Confirmed exploitation: None currently recorded ⚠️ Why It Matters. Veeam ONE monitors backup, virtualisation and management infrastructure. The official CVSS vector assigns High confidentiality, integrity and availability impact to both the vulnerable host and subsequent connected systems. Successful exploitation could potentially enable: • code execution on the agent host • credential and configuration theft • monitoring disruption • persistence and lateral movement • access to connected Veeam or virtualisation systems • interference with backup visibility and recovery operations 🛡️ Affected and Fixed Builds. Affected: Veeam ONE 13.0.2.6723 and earlier version 13 builds Fixed: Veeam ONE 13.1.0.7034 Public exploit details and a credible PoC were not located during this review, but Veeam warns that attackers may reverse-engineer security updates to target systems that remain unpatched. 🔍 Detection Focus. Investigate Veeam-related services spawning: cmd.exe powershell.exe pwsh.exe wscript.exe cscript.exe mshta.exe Also review: • unexpected outbound traffic from agent hosts • new services or scheduled tasks • unusual privileged logons • monitoring or reporting gaps • disabled alarms • suspicious activity against connected backup systems 🔧 Remediation. Upgrade immediately to Veeam ONE 13.1.0.7034. Restrict Veeam ONE components to trusted management networks and perform a compromise assessment on any vulnerable agent host that was reachable from an untrusted network. Patching closes the flaw but does not remove persistence or stolen credentials from an earlier compromise. 🔗 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-64633 🔗 Veeam Advisory: https://www.veeam.com/kb4892 #CyberForge #CVE202664633 #Veeam #VeeamONE #RCE #CodeInjection #CVSS10 #BackupSecurity #BlueTeam #ThreatHunting

    Post summary

    Veeam ONE hosts are exposed to a critical unauthenticated remote code execution vulnerability (CVE‑2026‑64633). A patch is available (13.1.0.7034); no public PoC or active exploitation has been reported.

    00001147
    545 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-64633 [HIGH PRIORITY] 🔗 https://exploitgrid.net/cve/CVE-2026-64633

    Post summary

    The post points to a high‑priority CVE with a link to an external exploit gallery, indicating that a Proof of Concept exists, but it does not provide technical or patch details.

    1000051
    29 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    🚨🚨🚨 『CVE-2026-64633 A vulnerability allowing remote unauthenticated code execution on the agent host.』 KB4892: Vulnerabilities Resolved in Veeam ONE 13.1 https://www.veeam.com/kb4892

    Post summary

    A new CVE (2026-64633) enabling remote unauthenticated code execution on Veeam ONE agent hosts is disclosed, and Veeam has addressed it in version 13.1 per KB4892.

    01000588
    7.0K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    🚨 Veeam patched multiple ONE vulnerabilities, including CVE-2026-64633—a maximum-severity flaw allowing unauthenticated remote code execution on affected agent hosts. Source: Cyber Security News #Veeam #RCE #PatchNow

    Post summary

    The post announces that Veeam has released patches for several ONE vulnerabilities, including the high‑severity CVE‑2026‑64633 that allows unauthenticated remote code execution, and urges users to apply the fix.

    0000055
    34 followersView on X
  • MY TECH BLOG@MyTechBlogJP
    Patch

    Veeam ONE に CVSS 10.0 の CVE-2026-64633。最も深刻な脆弱性の着弾点は、監視サーバーではなくエージェントが稼働するホストです。 ・対象は 13.0.2.6723 以前の v13 ・既定でエージェントは VBR 上に配置 ・公式の緩和策はなく 13.1 へ更新 https://mytech-blog.com/veeam-one-cve-2026-64633/ #Veeam

    Post summary

    The post discloses a high‑severity CVE-2026-64633 affecting Veeam ONE v13 and recommends upgrading to version 13.1 as the only mitigation.

    00000104
    177 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting Veeam ONE (CVE-2026-64633) https://vuldb.com/vuln/385880/cti

    Post summary

    CTI team reports widespread malicious activity targeting Veeam ONE CVE‑2026‑64633, indicating it is actively exploited.

    00000136
    2.3K followersView on X
  • Adam@seoscottsdale
    Patch

    3/4 Veeam ONE critical unauth RCE (CVE-2026-64633 CVSS 10) patched Aug 4/5. Linux OVSwrap local root (CVE-2026-64531) has public PoC for ~800 kernels. Backup & container hosts in the crosshairs. 4/4 Save this. Audit npm deps + KEV assets before coffee. Drop your stack in replies for priority mapping. #CyberSecurity #KEV #SupplyChain

    Post summary

    The tweet announces that Veeam ONE’s critical RCE was patched, mentions a public PoC for the OVSwrap local root flaw, and highlights the vulnerability’s severity.

    00000119
    12.4K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Veeam ONE Unauthenticated Remote Code Execution (CVE-2026-64633) A code-injection flaw in Veeam ONE (versions up to and including 13.0.2) allows remote, unauthenticated code execution on the monitoring agent host. Veeam ONE is the monitoring and reporting component of the Veeam Data Platform, and its agents run on many monitored hosts, so the exposed surface is broad. This one requires no authentication and no user interaction, scores the maximum CVSS 4.0 of 10.0, and is scope-changing with full CIA impact - the most severe of the August Veeam advisory batch (alongside the authenticated variant CVE-2026-58074). 👉Apply the Veeam ONE fix per Veeam KB4892 as a priority.

    Post summary

    The post announces CVE-2026-64633, a critical remote unauthenticated code injection flaw in Veeam ONE up to version 13.0.2, and urges users to apply the fix available via Veeam KB4892.

    00000155
    281 followersView on X

Explore more